Ardent Health Services ransomware attack diverted ambulances at US hospitals

Organization
Ardent Health Services
Exploit
Ransomware
Industry
Healthcare

Ardent Health Services, a Nashville-based hospital operator, detected unauthorized activity on its network on the morning of November 23, 2023, Thanksgiving Day. The company later confirmed the incident was a ransomware attack.

Ardent took its network offline as a containment measure, cutting user access to information technology applications including corporate servers, the Epic electronic health record system, internet access and clinical programs. Clinical staff reverted to paper records. The company runs about 30 hospitals and more than 200 sites of care across six states.

Emergency departments at multiple facilities went on divert status and ambulances were routed elsewhere. Reporting placed the disruption in Texas, New Mexico, New Jersey and Oklahoma, and The Record also listed Idaho. Elective and non-urgent procedures were rescheduled while systems were down.

Ardent said it reported the incident to law enforcement and brought in outside forensic and threat intelligence advisers. It did not name the group responsible. In its initial statements the company said it could not yet confirm the extent to which patient health or financial information had been affected, and it gave no timeline for restoring electronic medical records.

Access to Epic was restored on December 7, 2023, roughly two weeks after the attack, and emergency department divert status was lifted, though delays to non-emergency procedures continued as remaining systems came back. The HIPAA Journal later reported that around 40,000 patients may have had information exposed.

Sources